CVE-2026-0639: liteos_a has a missing release of memory vulnerability
Published Mar 16, 2026
·Updated
in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
Affected Software
3 affected components
OpenHarmony OpenHarmony<=6.0
liteos_a
Openatom Openharmony>=5.0.3<=6.0
Event History
Mar 16, 2026
CVE Published
via MITRE·07:08 AM
Data Sourced
via MITRE·07:08 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0639?
CVE-2026-0639 is considered a moderate severity vulnerability due to the potential for a local denial of service attack.
2
How do I fix CVE-2026-0639?
To fix CVE-2026-0639, update to the latest version of OpenHarmony that resolves the memory management issue.
3
Who is affected by CVE-2026-0639?
CVE-2026-0639 affects users running OpenHarmony v6.0 and prior versions, as well as liteos_a.
4
What kind of attack can be executed due to CVE-2026-0639?
CVE-2026-0639 allows a local attacker to cause a denial of service due to missing memory release.
5
Is CVE-2026-0639 easy to exploit?
Exploitation of CVE-2026-0639 is relatively straightforward for local attackers targeting affected systems.